Post

Defender for Cloud - Container Security - What's New in the Last 6 Months

Defender for Cloud - Container Security - What's New in the Last 6 Months

Defender for Cloud receives container-related changes throughout its regular release cycle. Looking back from January through July 2026, those updates cover posture management, vulnerability assessment, runtime protection, enforcement, sensor maintenance, private connectivity, and advanced hunting across Azure, AWS, and GCP.

The list is lifecycle-deduplicated: when a capability moved from preview to general availability during this period, only its latest GA state is shown. Preview entries remain where no later GA announcement exists.

Container Updates from January to July 2026

The table covers AKS, EKS, GKE, Azure Arc-enabled Kubernetes, private clusters, serverless containers, image scanning, runtime protection, Defender sensor releases, and container-relevant advanced hunting tables.

Each feature name links to the most specific Microsoft Learn page available.

MonthStatusScopeFeature or updateWhat changed
2026-07🟒 GAKubernetesContainer-level misconfiguration recommendationsAgentless KSPM evaluates individual containers; older cluster-level recommendations are deprecated.
2026-07🟒 GAAKSUpgrade AKS Version recommendationIdentifies the minimum upgrade required for vulnerable managed system pods.
2026-07🟒 GAEKS, GKERuntime-discovered image vulnerability assessmentExtends scanning beyond registry images to images found in running workloads.
2026-07🟒 GAEKS, GKEKubernetes node vulnerability assessmentAdds OS-level node vulnerability assessment equivalent to existing AKS coverage.
2026-07🟒 GAContainer imagesDocker Hardened image scanningAdds Defender Vulnerability Management coverage for Docker Hardened images.
2026-07🟒 GAAKS, Arc, AWS, GCPKubernetes misconfiguration enforcementAdds admission-time audit and blocking through automatic provisioning or Helm.
2026-07🟒 GAACA, ACI, ECS FargateServerless-container discovery and postureAdds inventory, misconfiguration and vulnerability findings, and attack-path analysis.
2026-07🟒 GAHelm, Arc for KubernetesDefender sensor v0.11 release lineBecame GA in July 2026 and is supported through July 2027.
2026-06🟒 GAAWS, GCPExpanded multicloud posture coverageAdds approximately 90 resource types and 200+ recommendations, including containers.
2026-06πŸ”΅ UpdateKubernetes, registriesExpanded container support for cloud scopesAdds K8s namespace, K8s cluster, multicloud registry, and repository scopes.
2026-06🟑 PreviewAWS, GCP60+ multicloud recommendationsAdds recommendations spanning containers and other resource categories.
2026-06🟑 PreviewPrivate EKS, GKE clustersDefender sensor v0.11.3Adds Defender sensor support for private EKS and GKE clusters.
2026-06🟒 GAMulticloud audit activityCloudAuditEvents advanced hunting tableExposes cloud audit activity for control-plane and container investigations.
2026-06🟒 GACloud and container DNSCloudDnsEvents advanced hunting tableExposes DNS activity from cloud infrastructure environments.
2026-06🟒 GAMulticloud workloadsCloudProcessEvents advanced hunting tableExposes process activity from multicloud hosted workloads.
2026-05🟑 PreviewPrivate Kubernetes clustersPrivate-cluster sensor protectionAdds gated deployment, binary-drift detection, and malware detection support.
2026-05🟑 PreviewEKS, GKEKubernetes-node malware detectionExtends node malware coverage beyond AKS.
2026-05🟒 GAAKS, EKS, GKEDirect Helm sensor deploymentReplaces installation scripts with environment-specific Helm commands.
2026-05🟒 GAContainers, container imagesIndividual vulnerability recommendationsReplaces legacy grouped container and image recommendations.
2026-05🟒 GAHelm, Arc, AKSSensor v0.10.5, v0.9.58 and v0.8.51Adds Nexus Baremetal compatibility plus dependency security and stability updates.
2026-04🟒 GAEKSBottlerocket runtime protectionAdds runtime protection for EKS clusters using Bottlerocket.
2026-04🟒 GAAKS, EKS, GKERuntime anti-malware detection and blockingAdds configurable alerting and blocking policies for malicious runtime executables.
2026-04🟒 GAAKS, EKS, GKEDNS Detection for KubernetesDetects malicious domains and DNS tunnelling through the Helm-deployed sensor.
2026-04🟒 GAAzure GovernmentDefender for Containers capabilitiesAdds agentless discovery, attack paths, vulnerability assessment, compliance, and runtime protection.
2026-04🟒 GAHelm, Arc for KubernetesSensor v0.9 and v0.10 release linesBoth became stable in April 2026 and are supported through April 2027.
2026-03🟒 GAAKS AutomaticKubernetes gated deploymentInstalls the sensor through Helm in kube-system, replacing the AKS add-on deployment.
2026-03🟑 PreviewContainer images, CI/CDCode-to-runtime enrichmentMaps runtime recommendations through registries and pipelines back to source code.
2026-03🟑 PreviewKubernetes policy enforcementCloudPolicyEnforcementEvents advanced hunting tableExposes policy decisions and metadata for cloud security gating events.
2026-03🟒 GA / 🟑 PreviewDefender sensorSensor security and platform updatesAdds Nexus compatibility, secret sanitisation, SELinux improvements, FIPS support, hardened images, and dependency fixes.
2026-02🟑 PreviewContainer workloadsBinary-drift blockingSensor v0.10.2 can block unauthorised runtime changes to container images.
2026-02🟒 GAContainer imagesMinimus and Photon OS scanningExtends image vulnerability scanning to both distributions.
2026-02🟒 GA / 🟑 PreviewDefender sensorSensor performance improvementsDelivered through stable v0.8.47 and preview v0.9.50.
2026-01🟑 PreviewDefender for ContainersMicrosoft Security Private LinkEnables private connectivity between Defender for Cloud and protected workloads through private endpoints.

Status key: 🟒 generally available, 🟑 preview, and πŸ”΅ functional update. Mixed sensor rows combine changes shipped across stable and preview sensor branches in the same month.

What Stands Out

The first clear shift is multicloud parity. EKS and GKE now receive runtime image and node vulnerability assessment that was previously associated mainly with AKS. Malware detection is moving in the same direction, although EKS and GKE node coverage is still in preview.

The second is the move from observation towards enforcement. Kubernetes misconfiguration enforcement can audit or block resources at admission time, while binary-drift blocking and gated deployment add controls closer to workload execution. I would still start these controls in audit mode and review the impact before blocking production deployments.

The third is better investigation data in Defender XDR. CloudAuditEvents, CloudDnsEvents, and CloudProcessEvents are now GA, while CloudPolicyEnforcementEvents remains in preview. These tables matter for container investigations even though their names are broader than Kubernetes - they expose the audit, DNS, process, and policy activity around the workload.

The table is a release summary, not a support guarantee. Check the linked support matrix before enabling a capability because availability can differ by cloud, Kubernetes distribution, deployment method, and sensor version.

Sources

Conclusion

Container security in Defender for Cloud changed quite a bit between January and July. The most useful improvements are not limited to another set of recommendations - Microsoft added private connectivity, more multicloud coverage, practical admission and runtime controls, serverless-container posture, and hunting tables that bring the resulting activity into Defender XDR.

The remaining previews are worth tracking, especially private-cluster protection, EKS and GKE malware detection, binary-drift blocking, and CloudPolicyEnforcementEvents. Those are the rows most likely to move again in the next release cycle.

This post is licensed under CC BY 4.0 by the author.